No advisories yet.
Solution
Update the affected components to their respective fixed versions.
Workaround
Remove template and host write permissions for non-admin users.
Mon, 09 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zabbix
Zabbix zabbix |
|
| Vendors & Products |
Zabbix
Zabbix zabbix |
Fri, 06 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 06 Mar 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions. | |
| Title | Unauthorized host creation via configuration.import API by low-privilege user with write permissions | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2026-03-09T20:54:45.380Z
Reserved: 2026-01-19T14:02:54.327Z
Link: CVE-2026-23925
Updated: 2026-03-09T20:54:42.228Z
Status : Awaiting Analysis
Published: 2026-03-06T09:15:56.100
Modified: 2026-03-09T13:35:34.633
Link: CVE-2026-23925
OpenCVE Enrichment
Updated: 2026-03-09T10:08:10Z